Loading…
Loading…

AI Expert
Johnie T Young is an AI expert and governance practitioner with deep experience helping fast-moving technology companies implement responsible AI practices at small-team scale. With a focus on practical, actionable frameworks, Johnie built AI Policy Desk to close the gap between enterprise-grade compliance tooling and the real-world needs of lean product teams. Before founding AI Policy Desk, Johnie worked across a range of technology companies advising on AI risk management, GDPR readiness, and EU AI Act compliance. With the rapid emergence of AI regulation globally, Johnie identified a clear need: governance resources written for 10-person teams, not Fortune 500 legal departments — practical templates, checklists, and guides that teams can pick up and use today.
221 articles by Johnie T Young
Copy-paste AI incident response plan template: 5 phases, role assignments, notification checklist, and timeline. Built for teams without a dedicated security or compliance function.
133 days until Connecticut SB 5 takes effect October 1, 2026. 10-step employer checklist: AEDT disclosure notices, bias audit requirements, anti-discrimination policy, and whistleblower protections. Who must comply and by when.
EEOC AI hiring compliance checklist 2026: 8 steps to assess disparate impact, obtain vendor bias documentation, and avoid EEOC liability when using AI tools for hiring, screening, or performance evaluation.
GPAI obligations in force since August 2, 2025. August 2, 2026 is when Commission fines activate. Four core obligations: technical documentation, training data summary, copyright opt-out, downstream operator info. Deadline NOT extended by EU Digital Omnibus.
GDPR Article 22 applies when AI makes fully automated decisions with legal or significant effects on individuals. Small-team compliance guide: when Article 22 is triggered, what rights it creates, and the three steps to comply.
GDPR Article 30 requires every company that processes personal data to maintain Records of Processing Activities (RoPA). AI tools create new processing activities, ChatGPT, Claude, Copilot each need an entry. Fill-in template pre-completed for 12 common AI tools.
Fill-in-the-blanks risk assessment template for third-party AI tools: 4-category risk matrix covering data risk, access risk, vendor risk, and regulatory risk, with scoring guide for go/no-go decisions.
Amazon KDP AI content policy timeline: the 2024 disclosure rollout, 2025 enforcement expansion, and what changed in April 2026. What the current official requirements are, and what KDP still hasn't addressed.
The TAKE IT DOWN Act took effect May 19, 2025. FTC enforcement began May 19, 2026. Covered platforms must remove NCII and AI-generated deepfakes within 48 hours of a verified request. Compliance checklist and what FTC enforcement looks like now.
EU AI Act Omnibus: nudification apps banned and AI watermarking required by December 2, 2026. Compliance checklist for providers and deployers, what must change, what's exempt, and penalties.
Texas TRAIGA compliance checklist for developers and deployers. Effective January 1, 2026: prohibited uses, documentation requirements, impact assessments, consumer notices, and the NIST safe harbor.
Amazon KDP disclosure 2026: AI-assisted vs AI-generated, the official definitions, which checkbox applies to your book, what happens if you pick wrong, and a 5-question decision flowchart. Covers text, images, and translations.